Re: Investigating validations & issuances - The high value IP space BGP Hijacks on 2017-12-12

2017-12-18 Thread CCSFN Postmaster via dev-security-policy
The Microsoft Volume Licensing Service Center (VLSC) is definitely affected, at least from my recent experience - i've been struggling with their service for the past week because the email address validations from Microsoft VLSC seem to be intercepted/blocked somewhere - i'm having

Re: Investigating validations & issuances - The high value IP space BGP Hijacks on 2017-12-12

2017-12-15 Thread Matthew Hardeman via dev-security-policy
(reposting as I originally accidentally sent to Tom Ritter only) Both are great questions. My short answers on those are #1 - yes, but as a courtesy with the implication being that those who don't take the time or trouble might catch a sideways glare if a certificate issuance is later

Re: Investigating validations & issuances - The high value IP space BGP Hijacks on 2017-12-12

2017-12-15 Thread Tom Ritter via dev-security-policy
This is an extremely good point. I wonder: 1. If Mozilla should ask/require CAs to perform this check. 2. If Mozilla should ask/require CAs to invest in the capability to make this check for future requests in the future (where we would require responses within a certain time period.) -tom On